There are two prevalent tutorials about HijackThis on the Internet currently, but neither of them explain what each of the sections actually mean in a way that a layman can understand.

By no means is this information extensive enough to cover all decisions, but should help you determine what is legitimate or not. The service needs to be deleted from the Registry manually or with another tool.

HijackThis uses a whitelist of several very common SSODL items, so whenever an item is displayed in the log it is unknown and possibly malicious. The full name is usually important-sounding, like 'Network Security Service', 'Workstation Logon Service' or 'Remote Procedure Call Helper', but the internal name (between brackets) is a string of garbage, like 'Ort'. Here is the Malwarebytes' Anti-Malware log: -------------------------------------------- Malwarebytes' Anti-Malware 1.14 Database version: 812 4:10:58 PM 01/06/2008 mbam-log-6-1-2008 (16-10-58).txt Scan type: Full Scan (C:\|D:\|) Objects scanned: 369681 Time elapsed: 1 hour(s), 18 Hijackthis Windows 10 Please be aware that when these entries are fixed HijackThis does not delete the file associated with it.

There is a tool designed for this type of issue that would probably be better to use, called LSPFix. Under the SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges key you may find other keys called Ranges1, Ranges2, Ranges3, Ranges4,...

Table of Contents Warning Introduction How to use HijackThis How to restore items mistakenly deleted How to Generate a Startup Listing How to use the Process Manager How to use the

To download the current version of HijackThis, you can visit the official site at Trend Micro.Here is an overview of the HijackThis log entries which you can use to jump to

the CLSID has been changed) by spyware. If the file still exists after you fix it with HijackThis, it is recommended that you reboot into safe mode and delete the offending file.

Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) dan_plus_o, Jun 2, 2008 #9 ceewi1 VIP Member Messages: 5,427 Your logs appear to be clean. Click Do a system scan and save a logfile.   The hijackthis.log text file will appear on your desktop.   Check the files on the log, then research if they are If you click on that button you will see a new screen similar to Figure 10 below. navigate here Once you restore an item that is listed in this screen, upon scanning again with HijackThis, the entries will show up again.

When a user, or all users, logs on to the computer each of the values under the Run key is executed and the corresponding programs are launched. Since the LSPs are chained together, when Winsock is used, the data is also transported through each of the LSPs in the chain. The log file should now be opened in your Notepad.

You should now see a new screen with one of the buttons being Open Process Manager.

F2 and F3 entries correspond to the equivalent locations as F0 and F1, but they are instead stored in the registry for Windows versions XP, 2000, and NT. By deleting most ActiveX objects from your computer, you will not have a problem as you can download them again.

When you fix these types of entries, HijackThis does not delete the file listed in the entry. They are also referenced in the registry by their CLSID which is the long string of numbers between the curly braces.

For F2, if you see UserInit=userinit.exe, with or without nddeagnt.exe, as in the above example, then you can leave that entry alone. If you would like to see what DLLs are loaded in a selected process, you can put a checkmark in the checkbox labeled Show DLLs, designated by the blue arrow in

valis replied Feb 10, 2017 at 4:59 PM Loading... scanning hidden autostart entries ... I didn't mean to click on it I was trying to highlight it so I could look it up on google and I guess I clicked too close to it and If you're not already familiar with forums, watch our Welcome Guide to get started.